Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 24.04 PostfixAdmin An Important Fix for XSS Attack USN-8242-2

PostfixAdmin could be made to run malicious JavaScript in the user's browser if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8242-2 May 07, 2026 postfixadmin vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: PostfixAdmin could be made to run malicious JavaScript in the user's browser if it received specially crafted input. Software Description: - postfixadmin: Virtual mail hosting interface for Postfix Details: USN-8242-1 fixed a vulnerability in CiviCRM. This update provides the corresponding fix for PostfixAdmin. Original advisory details: Takuya Aramaki discovered that Smarty, vendored in CiviCRM, did not properly escape JavaScript code. An attacker could possibly use this issue to conduct a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS postfixadmin 3.3.13-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8242-2 https://ubuntu.com/security/notices/USN-8242-1 CVE-2023-28447 . PostfixAdmin vulnerability could lead to malicious JavaScript execution in users' browsers through crafted input.. PostfixAdmin JavaScript Security Ubuntu Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 07, 2026 Important Ubuntu
172

Ubuntu 22.04 LTS USN-6550-1 moderate: postfixadmin denial of service

Several security issues were fixed in PostfixAdmin.. ========================================================================== Ubuntu Security Notice USN-6550-1 December 12, 2023 postfixadmin vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS (Available with Ubuntu Pro) - Ubuntu 20.04 LTS (Available with Ubuntu Pro) - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in PostfixAdmin. Software Description: - postfixadmin: Virtual mail hosting interface for Postfix Details: It was discovered that Smarty, that is integrated in the PostfixAdmin code, was not properly sanitizing user input when generating templates. An attacker could, through PHP injection, possibly use this issue to execute arbitrary code. (CVE-2022-29221) It was discovered that Moment.js, that is integrated in the PostfixAdmin code, was using an inefficient parsing algorithm when processing date strings in the RFC 2822 standard. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-31129) It was discovered that Smarty, that is integrated in the PostfixAdmin code, was not properly escaping JavaScript code. An attacker could possibly use this issue to conduct cross-site scripting attacks (XSS). (CVE-2023-28447) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS (Available with Ubuntu Pro): postfixadmin 3.3.10-2ubuntu0.1~esm1 Ubuntu 20.04 LTS (Available with Ubuntu Pro): postfixadmin 3.2.1-3ubuntu0.1~esm1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): postfixadmin 3.0.2-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6550-1 CVE-2022-29221, CVE-2022-31129, CVE-2023-28447 . Ubuntu Security Advisory USN-6571-1addresses security flaws found in Phabricator affecting several Ubuntu releases.. PostfixAdmin Security, Denial of Service Threats, XSS Attacks. . LinuxSecurity.com Team

Calendar 2 Dec 12, 2023 Ubuntu
87

Debian: DSA-2889-1 Moderate: SQL Injection In Postfixadmin Resolved

An SQL injection vulnerability was discovered in postfixadmin, a web administration interface for the Postfix Mail Transport Agent, which allowed authenticated users to make arbitrary manipulations to the database. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2889-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst March 28, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : postfixadmin CVE ID : CVE-2014-2655 An SQL injection vulnerability was discovered in postfixadmin, a web administration interface for the Postfix Mail Transport Agent, which allowed authenticated users to make arbitrary manipulations to the database. The oldstable distribution (squeeze) does not contain postfixadmin. For the stable distribution (wheezy), this problem has been fixed in version 2.3.5-2+deb7u1. For the testing distribution (jessie), and unstable distribution (sid), this problem has been fixed in version 2.3.5-3. We recommend that you upgrade your postfixadmin packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance PostfixAdmin's security by upgrading it to address SQL injection vulnerabilities on Debian platforms. Regularly apply patches and monitor dependencies to ensure robust protection.. Postfixadmin, SQL Injection Threat, Debian Advisory, Patch Security, Threat Resolution. . LinuxSecurity.com Team

Calendar 2 Mar 28, 2014 Debian
91

Gentoo GLSA 201209-18 Normal: Postfixadmin SQL Injection and XSS

Multiple vulnerabilities have been found in Postfixadmin which may lead to SQL injection or cross-site scripting attacks.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201209-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Postfixadmin: Multiple vulnerabilities Date: September 27, 2012 Bugs: #400971 ID: 201209-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Postfixadmin which may lead to SQL injection or cross-site scripting attacks. Background ========= Postfixadmin is a web-based management tool for Postfix-style virtual domains and users. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/postfixadmin < 2.3.5 > = 2.3.5 Description ========== Multiple SQL injection vulnerabilities (CVE-2012-0811) and cross-site scripting vulnerabilities (CVE-2012-0812) have been found in Postfixadmin. Impact ===== A remote attacker could exploit these vulnerabilities to execute arbitrary SQL statements or arbitrary HTML and script code. Workaround ========= There is no known workaround at this time. Resolution ========= All Postfixadmin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/postfixadmin-2.3.5" References ========= [ 1 ] CVE-2012-0811 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0811 [ 2 ] CVE-2012-0812 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0812 Availability =========== This GLSA and any updates to itare available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201209-18 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous security flaws identified in Postfixadmin may result in SQL injection and XSS attacks; updating is advised.. Postfixadmin, SQL Injection, XSS, Gentoo Advisory, Web Management. . LinuxSecurity.com Team

Calendar 2 Sep 27, 2012 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here